Denial-of-Service Vulnerability in SINUMERIK Products by Siemens
CVE-2018-11466
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 December 2018
Summary
A vulnerability exists in specific versions of Siemens' SINUMERIK products that enables a remote attacker to send specially crafted packets to port 102/tcp, potentially causing a Denial-of-Service condition or executing code within the context of the integrated software firewall. This issue allows exploitation without the need for user privileges or interaction, threatening the confidentiality, integrity, and availability of affected systems. As of the advisory's publication, there were no known public exploits for this vulnerability.
Affected Version(s)
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 808D V4.7 : All versions
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 808D V4.8 : All versions
SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SINUMERIK 828D V4.7 : All versions < V4.7 SP6 HF1 < SINUMERIK 828D V4.7 : All versions V4.7 SP6 HF1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved